Seeing if this is a big pain point for a lot of people? Comments are much appreciated ๐.
My company helps customers assess vendors but curious as to how vendors feel about the process. Anecdotes are helpful!
As a company that focuses in a security niche, specifically we offer IAM as a service for permissions and access control. We get these are part of doing business. We expect them and we have a great solution. We direct everyone to our online github pages which explain our security audits and practices.
However for our less security related apps which do have security impacts as a product, it has been less great, but we've been able to easily utilize our online pages as a good direction to send people to.
Most clients have no idea what they want, they are just following their internal process which says "get them to fill out this survey". To which we reply, "Our results are on our github, please follow up if there are any questions".
We never hear back.
Since this works so well, we've never considered picking another strategy. For example here is our: https://github.com/Rhosys/Handbook/blob/master/Security-Compliance.md
You could do the same thing.
@wparad Apologies for digging out an old post. Did you guys base that security response on any particular template, pull from a SOC2 based list of requirements, or you just rolled with the most common questions that came your way?
I pre-filled out a CAIQ-Lite survey in preparation for these, but haven't gotten to the point of submitting a full one to the public registry or publishing ours to the website.
Btw - It's awesome that your responses are shared publicly and something I now want to do sooner.
We collected a number of products that also have online handbooks and took inspiration from them. For instance Google's and GitLab's policies are also online. GitLab's is easier to find theirs.
Thanks for sharing how you do it. Are you consulting or do you have apps that people use?
Our business has two core focuses:
So both to answer your question. Why do you ask?
I could see someone assessing a consultant less but I'm surprised if they don't assess a cloud product that holds NPI. Might be a size/regional difference in the type of company you sell to vs the type of company I work with.
I'm not following, you are probably making some assumptions about our business. Where are you going with this?
I'm not really going anywhere with this. Just trying to understand if responding to security questionnaires is a pain point. I suppose for you guys, it is not.
This comment was deleted 6 years ago
This comment was deleted 6 years ago
It's not challenging, it's a time suck. Most clients have no idea what they're asking about and don't have anyone on their payroll equipped to understand what they're asking for.
Sometimes a questionnaire will come in for a company that clearly requires a higher maturity level than we're currently at. When those come in, either you need to waste time filling it out, or you need to convince a sales person that this fish they just bagged is a no go. Lose-lose
Thanks for the response.
When you say higher maturity - do you mean from a security perspective or just documentation of your security? (i.e. you don't patch or you patch but you don't have a policy around it)
What is your average contract size that you could be walking away from bc of the security requirements?
Security perspective for sure. Financial institutions are the worst - they have very hard to achieve requirements like customer managed encryption keys for sensitive content, SOC 2, etc. Stuff that you don't really get done at a SAAS until you're massive.
The contract size is often independent of the security requirements requested. A fortune 50 company might want to give the service a spin, but only request 50-100 seats. The sales guy froths at the mouth at the idea of bagging a fortune 50 that might eventually have a few thousand seats.
I honestly think a lot of it is messaging to the customer. For instance, if you show them how much you have in place with an avalanche of policies and also show them mitigating controls to vulnerabilities, I think it will get approved much faster.
Reason I say that is I could envision helping companies put together a 'packet' of information (including the creation of policies where there are none) that you could share with potential customers. I have a feeling the 'packet' would get approved a lot.